Bug #81216 [Opn->Csd]: Nullsafe operator leaks dynamic property name

From: Date: Sat, 04 Dec 2021 15:05:27 +0000
Subject: Bug #81216 [Opn->Csd]: Nullsafe operator leaks dynamic property name
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238165@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81216&edit=1 ID: 81216 Updated by: git@php.net Reported by: nikic@php.net Summary: Nullsafe operator leaks dynamic property name -Status: Open +Status: Closed Type: Bug Package: Scripting Engine problem PHP Version: 8.0.8 Block user comment: N Private report: N New Comment: Automatic comment on behalf of dstogov Revision: https://github.com/php/php-src/commit/307e476e86e19135976ba7e686558de68dbb9b29 Log: Fixed bug #81216 (Nullsafe operator leaks dynamic property name) Previous Comments: ------------------------------------------------------------------------ [2021-07-02 08:26:07] nikic@php.net Related To: Bug #81190 ------------------------------------------------------------------------ [2021-07-01 14:42:34] nikic@php.net Description: ------------ Split off from bug #81190: <?php $str = "foo"; null?->{$str . "bar"}; leaks the property name. The opcodes look like this: 0000 ASSIGN CV0($str) string("foo") 0001 T2 = CONCAT CV0($str) string("bar") 0002 T3 = JMP_NULL null 0004 0003 T3 = FETCH_OBJ_R null T2 0004 FREE T3 0005 RETURN int(1) Note that the CONCAT happens before the JMP_NULL. This is JMP_NULL is part of the delayed opline stack. Possibly we could get away with not using delayed oplines with nullsafe, because nullsafe cannot be used in write context, so not delaying should be safe. It will result in different evaluation order than non-nullsafe properties though. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81216&edit=1

« previous php.bugs (#238165) next »